Section: .. / 0710-advisories /
| /// File Name: |
glsa-200710-15.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-15 - Kees Huijgen discovered an error when checking the credentials which can lead to a login without specifying a password. This only occurs when auto login is configured for at least one user and a password is required to shut down the machine. Versions less than 3.5.7-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3367 | | Related CVE(s): | CVE-2007-4569 | | Last Modified: | Oct 15 19:09:18 2007 |
| MD5 Checksum: | 8333f83b98a00eca994e84c9460a9253 |
|
| /// File Name: |
glsa-200710-14.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-14 - Daniel B. Cid discovered that DenyHosts used an incomplete regular expression to parse failed login attempts, a different issue than GLSA 200701-01. Versions less than 2.6-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2962 | | Related CVE(s): | CVE-2007-4323 | | Last Modified: | Oct 15 19:08:52 2007 |
| MD5 Checksum: | 1aa762c9d1c32d75860754a54bfaa5ff |
|
| /// File Name: |
glsa-200710-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-13 - LT discovered that the match parameter in albums.php is not properly sanitized before being processed. The Apache development team also reported an error when handling user sessions. Versions less than 3.3.3.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3036 | | Related CVE(s): | CVE-2007-4437, CVE-2007-4438 | | Last Modified: | Oct 15 19:08:18 2007 |
| MD5 Checksum: | 4b55a73740a637f6c1539265dfdd484c |
|
| /// File Name: |
nssboard-xss.txt |
Description:
|
Nssboard, formerly Simple PHP forum, is susceptible to HTML injection vulnerabilities.
| | Author: | Casey Fitzpatrick | | File Size: | 1135 | | Last Modified: | Oct 15 19:07:56 2007 |
| MD5 Checksum: | f64b8010de079f20c1ce5d48eaab58aa |
|
| /// File Name: |
lfscbof.txt |
Description:
|
Live For Speed versions 0.5X10 and below suffer from a buffer overflow vulnerability in the client during skin handling.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | lfscbof.zip | | File Size: | 2728 | | Last Modified: | Oct 15 19:05:34 2007 |
| MD5 Checksum: | 59a87bd375a64f06c64ec4857d76a4b1 |
|
| /// File Name: |
sa27253.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for ampache. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct session fixation attacks.
| | Homepage: | http://secunia.com/advisories/27253/ | | File Size: | 2098 | | Last Modified: | Oct 15 19:01:16 2007 |
| MD5 Checksum: | cde331a39ff267cc2358549e0be812cb |
|
| /// File Name: |
sa27204.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in OpenSER, which can be exploited by malicious people to hijack user sessions.
| | Homepage: | http://secunia.com/advisories/27204/ | | File Size: | 2197 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | e0ce39eba853b275410556f416e91a78 |
|
| /// File Name: |
sa27229.txt |
Description:
|
Secunia Security Advisory - SUSE has issued updates for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27229/ | | File Size: | 3794 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | 03e60d46ea30d8c1c448ff42b8c02831 |
|
| /// File Name: |
sa27239.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27239/ | | File Size: | 2033 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | 22e30e9477d8484172b4f5cc1a7539ce |
|
| /// File Name: |
sa27241.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27241/ | | File Size: | 15415 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | 2d44b310e5b1a801d9cebd84a8c4c8e2 |
|
| /// File Name: |
sa27247.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for skktools. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/27247/ | | File Size: | 2055 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | a5d138edaedf73155a922a67c5baabdd |
|
| /// File Name: |
sa27254.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for denyhosts. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27254/ | | File Size: | 2023 | | Last Modified: | Oct 15 18:42:41 2007 |
| MD5 Checksum: | 776dac9dd7702462455ad4c896e9af89 |
|
| /// File Name: |
ie7-bypass.txt |
Description:
|
Internet Explorer 7 suffers from a simple filter bypass vulnerability.
| | Author: | laurent gaffi | | File Size: | 1117 | | Last Modified: | Oct 15 17:07:52 2007 |
| MD5 Checksum: | aced5e3e2ef6a0fa0185c19aea5c13f6 |
|
| /// File Name: |
ciscosip.txt |
Description:
|
Cisco CallManager and OpenSer suffer from a SIP toll fraud and authentication forward vulnerability.
| | Author: | Humberto J. Abdelnur, Olivier Festor, Radu State | | File Size: | 2379 | | Last Modified: | Oct 15 16:55:11 2007 |
| MD5 Checksum: | 38d7172765e6072c201fcb9141c23afe |
|
| /// File Name: |
sa25878.txt |
Description:
|
Secunia Security Advisory - Andy Polyakov has reported a vulnerability in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/25878/ | | File Size: | 2355 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | f3631e0cd8d5b4749c1a692e1cbd2ddd |
|
| /// File Name: |
sa27171.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in SQL-Ledger, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/27171/ | | File Size: | 2186 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | eff9e896524ba7815ca05180bbd7116f |
|
| /// File Name: |
sa27183.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users and malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27183/ | | File Size: | 3219 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | f0efed73d3f0948ed8eb547fe765b045 |
|
| /// File Name: |
sa27228.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for XOrg. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/27228/ | | File Size: | 26006 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | 91a42077edbf8cf0a08b67497aa0d320 |
|
| /// File Name: |
sa27244.txt |
Description:
|
Secunia Security Advisory - Stefan Monnier has reported a vulnerability in Tramp, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/27244/ | | File Size: | 2262 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | 0925d1bd9cfd017e69ef7e96de6149a7 |
|
| /// File Name: |
sa27249.txt |
Description:
|
Secunia Security Advisory - A vulnerability with an unknown impact has been reported in IBM WebSphere Application Server.
| | Homepage: | http://secunia.com/advisories/27249/ | | File Size: | 2540 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | 60c0cf2552c5b95401fb7958e8578fc2 |
|
| /// File Name: |
sa27258.txt |
Description:
|
Secunia Security Advisory - IRCRASH has reported a vulnerability in Softbiz Recipes Portal Script, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/27258/ | | File Size: | 2314 | | Last Modified: | Oct 15 16:43:14 2007 |
| MD5 Checksum: | c045fc91bb8f26f6e1cccb0b5dea6a38 |
|
| /// File Name: |
dsa-1381-2.txt |
Description:
|
Debian Security Advisory 1381-2 - Several local vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. This is an update to DSA-1381-1 which included only amd64 binaries for linux-2.6. Builds for all other architectures are now available, as well as rebuilds of ancillary packages that make use of the included linux source.
| | Homepage: | http://www.debian.org/security | | File Size: | 38855 | | Related CVE(s): | CVE-2006-5755, CVE-2007-4133, CVE-2007-4573, CVE-2007-5093 | | Last Modified: | Oct 12 21:36:36 2007 |
| MD5 Checksum: | ca85f0d74f6a9ab241328ff4acc9f934 |
|
| /// File Name: |
glsa-200710-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-12 - Hamid Ebadi discovered a boundary error in the intT1_EnvGetCompletePath() function which can lead to a buffer overflow when processing an overly long filename. Versions less than 5.0.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3089 | | Related CVE(s): | CVE-2007-4033 | | Last Modified: | Oct 12 21:34:55 2007 |
| MD5 Checksum: | 64b754a15d2a7d3ea0cfb25ea824f54c |
|
| /// File Name: |
glsa-200710-11.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-11 - iDefense reported that the xfs init script does not correctly handle a race condition when setting permissions of a temporary file. Sean Larsson discovered an integer overflow vulnerability in the build_range() function possibly leading to a heap-based buffer overflow when handling QueryXBitmaps and QueryXExtents protocol requests. Sean Larsson also discovered an error in the swap_char2b() function possibly leading to a heap corruption when handling the same protocol requests. Versions less than 1.0.5 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3813 | | Related CVE(s): | CVE-2007-3103, CVE-2007-4568, CVE-2007-4990 | | Last Modified: | Oct 12 21:34:47 2007 |
| MD5 Checksum: | eca0eedd0d3be5eb886c2d8371bea49d |
|
| /// File Name: |
glsa-200710-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200710-10 - skkdic-expr.c insecurely writes temporary files to a location in the form $TMPDIR/skkdic$PID.{pag,dir,db}, where $PID is the process ID. Versions less than 1.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2618 | | Related CVE(s): | CVE-2007-3916 | | Last Modified: | Oct 12 21:33:24 2007 |
| MD5 Checksum: | b14d3a611f0ae5d3adf8eeb0a06e9743 |
|
|
|
|
|